Custody System Traces AI Agent Memory to Its Source to Contain Poisoned Data
A new open-source framework called Custody, built for Google Cloud's All Things Agentic Hackathon, addresses a critical gap in AI agent memory systems: tracking content trust, not just authorship. Google's Agent Development Kit labels memories by author but cannot distinguish between safe model-generated content and data restated from a compromised external source. Custody solves this by building a derivation graph that links every stored memory back through its chain of origin, enabling precise revocation when a source is found to be compromised. In tests on a 600-record dataset, the system contained a single bad tool's impact by revoking only 40 derived records rather than wiping all fleet memory. The framework enforces a strict rule that AI models can draft language but cannot write trust or origin fields, a constraint verified at the code structure level on every build commit.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in